WIRELESS FIREWALL CONNECTION TRACE Purpose: follow one authorized connection through the actual network path. Article: https://yenra.com/wireless-firewall/ Prepared: September 8, 2026. Plain-text working record; edit a local copy. Use only on networks and endpoints you administer or are authorized to test. Save a recoverable configuration. Keep credentials and sensitive payloads out of this record. Record exact addresses privately where appropriate. SETUP Tester / service owner / test date and timezone: Firewall product, version and configuration backup reference: Approved task and expected application result: Client address, address family, subnet, selected route and gateway: AP mode, SSID, VLAN and firewall ingress interface: Destination hostname, resolved address, protocol and destination port: Destination type: other network / Internet / firewall itself TRACE (repeat for each observation; use local timestamps with UTC offsets) Observation time: Capture or log location and direction: Original source address:port -> destination address:port: Translated addresses at this point, if any: Matching rule / rule order / automatic or floating rules checked: New connection or existing state; state identifier if available: Server listener, host firewall and return-route evidence: Application result and exact error, if any: Evidence file or log reference: CHANGE AND VERIFY Evidence-supported cause: One narrow change and rollback step: Fresh permitted connection: expected / observed / evidence Separately approved blocked-service test: expected / observed / evidence Temporary logging or exceptions removed: Final configuration reference / owner / follow-up: FICTIONAL WORKED PATH (not production configuration) 192.168.20.25 -> 192.168.40.10, destination TCP 443, routed between subnets. Inspect client-facing ingress rules. Source port is assigned by the client. Check the actual application, not only ping. A TLS error is a different stage from a TCP timeout. Existing state can reflect an earlier decision. Platform context: pfSense interface-tab and NAT ordering documented at https://docs.netgate.com/pfsense/en/latest/firewall/fundamentals.html https://docs.netgate.com/pfsense/en/latest/nat/process-order.html Use your actual platform's complete processing order.